ELF_XORDDOS.AT
December 11, 2015
ALIASES:
DoS:Linux/Xorddos.A (Microsoft); a variant of Linux/Xorddos.C trojan (ESET); HEUR:Trojan-DDoS.Linux.Xarcen.a (Kaspersky); Trojan horse Linux/DDoS.XOR (AVG);
PLATFORM:
Unix,Linux
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
INFORMATION EXPOSURE:
Threat Type: Backdoor
Destructiveness: No
Encrypted: Yes
In the wild: Yes
OVERVIEW
This backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
File Size:
625817 bytes
File Type:
ELF
Memory Resident:
Yes
Initial Samples Received Date:
07 Dec 2015
Arrival Details
This backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This backdoor drops the following copies of itself into the affected system:
- /var/run/gcc.pid
- /lib/libudev.so
Autostart Technique
This backdoor drops the following files:
- /etc/cron.hourly/gcc.sh
Other Details
This backdoor connects to the following possibly malicious URL:
- http://pcdown.{BLOCKED}s.com:8080/cfg.rar
- http://soft8.{BLOCKED}s.com:2208
- {BLOCKED}.{BLOCKED}.246.145:2208
- baidu.{BLOCKED}s.com:2208